PT-2025-25174 · K7 · K7 Security Anti-Malware Suite
Carlos Garrido
·
Published
2025-06-10
·
Updated
2025-09-17
·
CVE-2025-1055
CVSS v3.1
5.6
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
K7 Security Anti-Malware suite (affected versions not specified)
Description
A flaw in the K7RKScan.sys driver allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges. This issue stems from missing access control in the driver's IOCTL handler, enabling unprivileged users to perform privileged actions in kernel space. Successful exploitation can lead to denial of service by disrupting critical services or privileged applications.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
K7 Security Anti-Malware Suite